Guided buildcore8 steps~20 min5 devices
NAT to the internet
Hide two private office LANs behind the single public address your provider gave you.
What you'll be able to do: Two private LANs share one public address on the internet: every packet leaves the office as 203.0.113.2, the provider's anti-spoofing filter lets it through, and the translation table shows exactly which inside host each one belongs to.
Topics: NAT · PAT overload · RFC 1918 · Default route · Public vs private addressing
What you'll build
- Edge — a router, the office router that owns the only public address
- ISP — a router, the provider's router, standing in for the internet
- PC-A — a pc, a workstation on the first office LAN
- PC-B — a pc, a workstation on the second office LAN
- WEB1 — a server, a public web server out on the internet
Step by step
1. Place the edge router and address the first LAN
Every office reaches the internet through one router with a foot in both worlds. Drag a router on, name it Edge, and give Gi0/0 the address 192.168.10.1. That range comes out of RFC 1918, the block reserved for private use — which is precisely why it is going to need translating before it can leave the building.
On Edge — Name the router and address the first inside LAN
enable configure terminal hostname Edge interface Gi0/0 ip address 192.168.10.1 255.255.255.0 no shutdown exit endCheck: run
show ip interface briefon Edge and look forGi0/0 192.168.10.1 YES manual down down.Why: RFC 1918 sets aside three ranges — 10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16 — that any organisation may use internally without asking anyone. The price of that freedom is that they are not unique: thousands of networks use the same addresses, so the public internet does not carry them at all.
2. Put a workstation on the first LAN
Cable a PC into Gi0/0 and give it an address from the same /24 with the router as its default gateway. A host holding a private address is not crippled — inside the office it is complete and fully usable. The address only becomes a problem at the moment it tries to leave.
- Cable PC-A Eth0 ↔ Edge Gi0/0
On PC-A — Name the workstation and set address, mask and gateway in one line
hostname PC-A ipconfig Eth0 192.168.10.10 255.255.255.0 192.168.10.1Check: run
route printon PC-A and look for0.0.0.0 0.0.0.0 192.168.10.1 Eth0.Why: NAT is invisible to the host: PC-A keeps using its private address as the source of every packet it sends and never learns that the address is rewritten at the edge. Nothing on the PC changes when NAT is added later, which is what makes it possible to add translation to a network that is already running.
3. Add a second private LAN on the other port
Offices are rarely one subnet, and the word "overload" only means something once several hosts are competing for one public address. Give Gi0/1 a second private range and hang PC-B off it. The two LANs can already talk to each other — routing between directly connected networks is the router's ordinary day job and needs no extra configuration.
- Cable PC-B Eth0 ↔ Edge Gi0/1
On Edge — Address the second inside LAN
enable configure terminal interface Gi0/1 ip address 192.168.20.1 255.255.255.0 no shutdown exit endOn PC-B — Name the second workstation and address it in the second LAN
hostname PC-B ipconfig Eth0 192.168.20.10 255.255.255.0 192.168.20.1Check: run
show ip routeon Edge and look forC 192.168.20.0/24 is directly connected, Gi0/1.Why: Translation happens only where traffic crosses from an inside interface to an outside one, never between two inside networks. PC-A and PC-B talk with their real addresses because both subnets are connected to Edge, and the translation added later will touch only traffic leaving through the WAN port.
4. Rent a link to the provider
Drag in a second router to play the provider and join the two with a serial WAN cable. The /30 between them carries exactly two usable addresses, and 203.0.113.2 on Edge is the only public address this office owns — one address, for every host behind it. Remember that number; the rest of the build is about making it stretch.
- Cable Edge Se0/0/0 ↔ ISP Se0/0/0 (serial)
On ISP — Name the provider router and address its end of the WAN link
enable configure terminal hostname ISP interface Se0/0/0 ip address 203.0.113.1 255.255.255.252 no shutdown exit endOn Edge — Address the office end of the WAN link
enable configure terminal interface Se0/0/0 ip address 203.0.113.2 255.255.255.252 no shutdown exit endCheck: run
show ip interface briefon Edge and look forSe0/0/0 203.0.113.2 YES manual up up.Why: Public IPv4 addresses are scarce — the free pool ran out years ago — so a small customer is usually given a handful, often exactly one, on a link sized to fit. 203.0.113.0/24 itself is one of the ranges reserved for documentation, which is why labs and textbooks use it instead of someone's real address.
5. Put a public server on the far side
Give the provider a second network with a web server on it. 198.51.100.50 is a public address in every sense that matters: globally unique, routable, and belonging to one machine anywhere on earth — the opposite of the two LANs behind Edge.
- Cable WEB1 Eth0 ↔ ISP Gi0/0
On ISP — Address the provider's public LAN
enable configure terminal interface Gi0/0 ip address 198.51.100.1 255.255.255.0 no shutdown exit endOn WEB1 — Name the server and give it a public address and gateway
hostname WEB1 ipconfig Eth0 198.51.100.50 255.255.255.0 198.51.100.1Check: run
show ip routeon ISP and look forC 198.51.100.0/24 is directly connected, Gi0/0.Why: Uniqueness is what makes an address routable across networks you do not control: every provider on the path can hold one route toward 198.51.100.0/24 and know it leads to exactly one place. A private range can never offer that, because the same prefix is in use behind thousands of different routers at once.
6. Point the office at the provider
Edge knows its own three connected networks and nothing else in the world. One default route hands every unknown destination to the provider. Ping 198.51.100.50 from PC-A now and it answers — hold that result lightly, because the packet just crossed the provider carrying a source address of 192.168.10.10.
On Edge — Send everything Edge does not recognise out of the WAN link
enable configure terminal ip route 0.0.0.0 0.0.0.0 203.0.113.1 endOn PC-A — Try the public server for the first time
ping 198.51.100.50Check: run
show ip routeon Edge and look forS* 0.0.0.0/0 via 203.0.113.1, Se0/0/0.Why: Longest-prefix match decides which route wins: a /24 beats a /16, and anything beats the /0 of a default route, which matches every destination with zero bits in common. Adding a default therefore changes nothing for Edge's connected LANs; it only gives a destination to traffic that would otherwise have been dropped.
7. The provider filters private sources, and the ping dies
192.168.10.10 is not one address — it is millions of them, live in every office on earth at the same moment, so no provider will carry it and no reply could ever find its way home. Install the RFC 1918 anti-spoofing filter that every real carrier runs on its customer-facing port, and watch both workstations go dark one hop after they leave the building.
On ISP — Refuse any packet arriving from the office with a private source address
enable configure terminal ip access-list extended NO-PRIVATE deny ip 192.168.0.0 0.0.255.255 any deny ip 10.0.0.0 0.255.255.255 any deny ip 172.16.0.0 0.15.255.255 any permit ip any any exit interface Se0/0/0 ip access-group NO-PRIVATE in endOn PC-A — Try the same ping again, now that the provider is filtering
ping 198.51.100.50Check: run
show access-listson ISP and look for10 deny ip 192.168.0.0 0.0.255.255 any.Why: A packet's source address is only a claim, and a private one cannot be traced to any one customer, so providers drop packets whose source could not legitimately come from the customer's link — the practice known as ingress filtering, described in BCP 38. It stops spoofed and unroutable traffic at the edge, before it can enter the provider's network.
8. Translate the whole office onto one public address
NAT overload — PAT — rewrites the source of every outbound packet to the router's own public address, and remembers which inside host it belonged to by handing each conversation its own port number. Mark the two LAN ports `inside`, mark the WAN port `outside`, list the private ranges allowed to translate, then commit the rule. Read `show ip nat translations` afterwards: 192.168.10.10 and 192.168.20.10 both leave as 203.0.113.2, told apart only by port — that is the whole trick behind the word "overload".
On Edge — Declare which side is inside and which is outside
enable configure terminal interface Gi0/0 ip nat inside exit interface Gi0/1 ip nat inside exit interface Se0/0/0 ip nat outside exit endOn Edge — Select the private ranges, then translate them onto the WAN address
enable configure terminal access-list 1 permit 192.168.10.0 0.0.0.255 access-list 1 permit 192.168.20.0 0.0.0.255 ip nat inside source list 1 interface Se0/0/0 overload endOn PC-A — The same ping, now with a public source address
ping 198.51.100.50On PC-B — And from the second LAN, sharing that one address
ping 198.51.100.50Check: run
show ip nat translationson Edge and look foricmp 203.0.113.2:1024 192.168.10.10:1024 198.51.100.50.Why: Replies come back addressed to 203.0.113.2 and the port Edge assigned — a destination the provider can route — and Edge looks that port up in its translation table to rewrite the packet back to the right inside host. The access list only selects which sources are translated: traffic it does not match is not blocked, it simply leaves untranslated.
The theory behind it
More in Network services
- Let the router hand out the addresses — Build a four-device office LAN, address one PC by hand, then put a DHCP pool on the router so the next machine configures itself.
- One DHCP server for every floor — Serve a user floor from a central DHCP server on another subnet — watch the first request die at the router, then relay it with ip helper-address.
- Let the core switch hand out the addresses — Run two department VLANs, their gateways and their DHCP pools on a single switch — and find out why a perfect pool can still hand out nothing.
- Give the whole network one clock — Build an NTP hierarchy from HQ to a branch switch, read the strata hop by hop, then find the security ACL that silently broke time while ping kept working.
- Lock management down to SSH — Make a switch manageable from the admin subnet, then harden it: RSA keys, SSH version 2, a local account, and VTY lines that refuse everything but SSH.
Build it for real
The lab walks you through these steps and ticks each one off as your network starts working.
Open in the lab